CVE-2022-25498: Code Injection
Published Mar 15, 2022
·Updated
CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.
Affected Software
1 affected component
CuppaCMS CuppaCMS=1.0
Event History
Mar 15, 2022
CVE Published
via MITRE·05:29 PM
Data Sourced
via MITRE·05:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25498?
CVE-2022-25498 has a high severity level due to its potential for remote code execution.
2
How do I fix CVE-2022-25498?
To fix CVE-2022-25498, users should update CuppaCMS to the latest version that addresses this vulnerability.
3
What types of attacks can CVE-2022-25498 enable?
CVE-2022-25498 can enable attackers to execute arbitrary code remotely on the affected system.
4
Which versions of CuppaCMS are affected by CVE-2022-25498?
CVE-2022-25498 specifically affects CuppaCMS v1.0.
5
Where can I find more information about CVE-2022-25498?
More information about CVE-2022-25498 can be found in the issue tracker on the CuppaCMS GitHub repository.